Forum Discussion
MDATP Integration - Unsanctioned Apps - Allow for some users?
Thanks Dean_Gross
I can see how you can scope/filter some policy types to specific users and groups, but the exact scenario I am looking for as an example is, say I have a group of users I want to allow access to Jira for and block for all other users.
If I tag Jira as an unsanctioned app in the Cloud app catalog, I assume this blocks it for all users.
How can I create a policy to block for all users except a specific group?
If I search the cloud app catalog for atlassian Jira and choose "create policy from search" to scope the policy to Jira specifically, the criteria you can choose from to build your filter within the policy doesn't include the ability to add user or group scoping filters as shown in the attached screen grab.
I cant see that scoping sanctioned and unsanctioned apps per user/group is possible in this manner
If I create an access control policy I can scope the policy to specific users but the apps I can choose from are only the apps I have onboarded to Azure AD, not the entire list of apps from the cloud app catalog.
Thanks
Paul